CVE Tools

Миллионам сайтов на WordPress угрожает уязвимость в плагине для резервного копирования

Хакер (xakep.ru)By Мария Нефёдова

PatchWordPressAll-in-One WP Migration and Backup

Our summary

A critical SQL injection vulnerability, identified as CVE-2026-19949 with a CVSS score of 8.8, has been discovered in the All-in-One WP Migration and Backup plugin for WordPress. The flaw allows unauthenticated attackers to achieve remote code execution by exploiting improper escaping of backslashes and quotes during database restoration from .wpress archives. Approximately 3.2 million sites are currently affected because they have not yet updated to the fixed version. ServMask released patch version 7.110 on August 20, 2026, but only about 35% of users have applied the update so far, leaving the majority exposed to potential compromise.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store